Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Michael Furman — SameSite Cookies

36 min3 september 2020

Om avsnittet

Michael Furman is the Lead Security Architect at Tufin, and is responsible for the security and Security Development Lifecycle (SDL) of Tufin software products. Michael is passionate about application security for over 13 years already and evangelizes about application security at various conferences (including OWASP conferences) and security meetups. Michael joins us to break down SameSite cookies, which are all the rage in browsers these days. He describes what they are, the threats they counter, and how SameSite + the Synchronizer Token Pattern work together to counter CSRF. We hope you enjoy this conversation with.... He's worked in this space for 13 years and evangelizes AppSec at various conferences, including OWASP and security meetups.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Michael Furman is the lead security architect at Tufin and is responsible for the security and secure development lifecycle of Tufin software products.
Learn more about Security Journey

Connect with Michael Furman:
Tufin
Chromium

Mentioned in this episode:
Tufin
Chromium

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Meet Michael Furman: Michael Furman — SameSite Cookies
02:17 Excellent. And so to get started, what we usually do is
04:54 Yeah, and I'll definitely second what you're saying about application security
07:17 Okay. And so SameSite's been around then for just a couple
08:52 That makes sense in terms of some of the things that
11:19 Yeah, and I think the last I heard for the previous
14:37 So with the— what you're modeling in the test csrf.htm here
17:09 Yeah. So one of the patterns that we've used in the
19:14 It sounds like you could still use the synchronizer pattern, but
30:39 We can only hope and dream that that is a world
32:29 Yeah, that's great. That provides our users with some additional information

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.